Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Reddcoin qa-assets

Test assets for the Reddcoin Core unit/fuzz test suites, consumed via DIR_UNIT_TEST_DATA / DIR_FUZZ_IN in ci/test/04_install.sh.

unit_test_data/script_assets_test.json

Vectors for script_tests/script_assets_test. Regenerated for Reddcoin because Reddcoin's CTransaction carries the peercoin-style nTime field, so the upstream Bitcoin (no-nTime) vectors fail to deserialize.

Generated with the Reddcoin-adapted test/functional/feature_taproot.py --dumptests (see src/test/fuzz/script_assets_test_minimizer.cpp for the assembly recipe).

fuzz_seed_corpus/

Seed inputs for test/fuzz/test_runner.py, one directory per fuzz target.

Produced against a Reddcoin fuzz binary configured the way CI configures it:

./configure --enable-fuzz --disable-wallet \
  --with-sanitizers=fuzzer,address,undefined,integer CC=clang CXX=clang++

Built in two stages.

1. Merge the upstream corpora. bitcoin-core/qa-assets keeps its inputs in fuzz_corpora/, renamed from fuzz_seed_corpus/ some time after the v22 base this fork tracks. libFuzzer's -merge=1 keeps only inputs that reach new coverage under the Reddcoin binary, so anything meaningless here is dropped rather than carried:

test/fuzz/test_runner.py --m_dir <upstream>/fuzz_corpora <corpus>

132 of the 179 targets have an upstream counterpart. The remainder do not, mostly because upstream has since consolidated the process_message_* family into a single target and renamed several *_deserialize ones.

2. Extend by generation. This covers the targets with no upstream corpus and explores paths specific to this fork, such as the PoSV transaction versions, the transaction nTime field and vchBlockSig:

test/fuzz/test_runner.py -g <corpus>

Consuming these assets does not require regenerating them. CI fetches the commit pinned in ci/test/00_setup_env.sh.

Two things that will bite when regenerating

Point TMPDIR at somewhere roomy. Every fuzz process leaves a datadir of about 17 MB behind under the system temp directory, and a merge across the whole suite accumulated roughly 26 GB of them. test_runner.py replaces the environment it passes to the binary, so TMPDIR is only honoured because it is forwarded explicitly.

On kernels that default vm.mmap_rnd_bits to 32 (6.8 and later), ASan's shadow mapping collides with ASLR and instrumented binaries segfault at random, independent of the target. Either lower it with sysctl -w vm.mmap_rnd_bits=28 or prefix the run with setarch -R.

About

Test assets (unit_test_data, fuzz_seed_corpus) for the Reddcoin Core test suites

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors